The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.
History

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow Yandex Provider
Vendors & Products Apache
Apache airflow Yandex Provider

Mon, 10 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.
Title Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable
Weaknesses CWE-639
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-08-10T18:18:20.026Z

Updated: 2026-08-12T15:43:17.688Z

Reserved: 2026-07-31T19:39:38.817Z

Link: CVE-2026-68871

cve-icon Vulnrichment

Updated: 2026-08-10T18:21:24.132Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-10T19:17:30.463

Modified: 2026-08-12T20:50:58.370

Link: CVE-2026-68871

cve-icon Redhat

No data.